Description
Cross-site scripting (XSS) vulnerability in IFrame type Remote Apps in Liferay Portal 7.4.0 through 7.4.3.30, and Liferay DXP 7.4 before update 31 allows remote attackers to inject arbitrary web script or HTML via the Remote App's IFrame URL.
Remediation
References
Related Vulnerabilities
Werkzeug WSGI Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-25577)
WordPress Plugin SendGrid Security Bypass (1.11.8)
WordPress Plugin Font Uploader 'font-upload.php' Arbitrary File Upload (1.2.4)
WordPress 4.4.x Cross-Site Request Forgery (4.4 - 4.4.17)
WordPress Plugin WP-HR Manager:The Human Resources Unspecified Vulnerability (2.9.4)